nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-1473 CVE-2024-1473
MEDIUM
Coming Soon & Maintenance Mode by Colorlib <= 1.0.99 - Information Exposure
Record summary
CVE-2024-1473 has a selected CVSS score of 5.3 (medium).
Description
The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.99 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page contents via REST API thus bypassing maintenance mode protection provided by the plugin.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
coming_soon_\&_maintenance_modeBrowse colorlib / coming_soon_\&_maintenance_modeDefault status: unknown | CVE List | Through 1.0.99 | affected |
Coming Soon & Maintenance Mode by ColorlibBrowse colorlibplugins / Coming Soon & Maintenance Mode by ColorlibDefault status: unaffected | CVE List | Through 1.0.99 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3058925/colorlib-coming-soon-maintenance/trunk/colorlib-coming-soon-and-maintenance-mode.php wordpress.org
https://wordpress.org/plugins/colorlib-coming-soon-maintenance wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/48dc10a9-7bb9-401f-befd-1bf620858825?source=cve